Qoqa Virus

7-day Free Trial w/Credit card, no charge upfront or if you cancel up to 2 days before expiration; Subscription price varies per region w/ auto renewal unless you timely cancel; notification before you are billed; 30-day money-back guarantee; Read full terms and more information about free remover.

*Qoqa is a variant of Stop/DJVU. Source of claim SH can remove it.


Qoqa is a new Ransomware infection that works by encrypting your most valuable files and keeping them hostage for a ransom. The Qoqa ransom-demanding note reveals the consequences of the attack and informs you about how much you have to pay.

The .Qoqa virus file ransom note

If you’ve been compromised by Ransomware, coming to this site is definitely the right thing to do. One of the new types of ransomware is called Qoqa, and we think it’s the one that has probably encrypted your files and deprived you from your access to them. If that’s the case, we’ll try to provide you with information about what you can do to deal with the consequences. We will also provide you with a thorough removal guide to find and remove Qoqa from your device. In the same guide you will also find instructions that could help you potentially recover some of the encrypted files. However, with the intention of full disclosure, we must note that we cannot guarantee a 100% recovery in all cases of infection. Ransomware is a very stealthy malware and its complex encryption algorithms can’t always be reversed successfully. Still, we’ve created this article to help the victims of this cyber threat to safely remove it and to provide more information about its methods of operation.

The Qoqa virus

The Qoqa virus is a cryptovirus that works differently from most traditional pieces of malware. Instead of corrupting your files, the Qoqa virus “simply” holds them hostage after first encrypting them.

Ransomware viruses usually enter their victims’ system via stealth and then proceed to conduct their evil agenda just as stealthily. This typically includes searching the victim’s computer for specific files such as audio and video files, documents, executable files, images, databases, and even some files related to the operating system. After completion of the scan, Qoqa, Qowd, Iotr or any other cryptovirus of this type, would typically start making encrypted copies of the detected files. At the same time, it will also erase the originals, leaving the victim with a bunch of useless encrypted information that no program can recognize or access. When all that’s done, the virus then generates a ransom note on the computer’s screen in order to inform the victims that they need to pay a ransom to decrypt their files.
In many cases, the ransom is demanded in bitcoins (or some other cryptocurrency). That’s because this type of cryptocurrency is very hard for the authorities to trace, which mostly guarantees that hackers won’t get brought to justice.

The Qoqa file decryption

The Qoqa file decryption is a complex process that requires advanced coding skills. Reversing the Qoqa file encryption successfully is not guaranteed even after the application of the corresponding decryption key.

Qoqa File

The hackers behind the Ransomware will typically try to scare their victims into believing that there is no other way to access the encrypted files save for paying the ransom. In exchange for the money, the crooks promise to send a unique decryption key with the help of which the victims can reverse the encryption and bring the files back to normal. Sadly, there have been cases where the intimidated users have paid the required ransom amount and have never received the special decryption key. There have also been cases where the victims have been blackmailed for more money after they’ve paid once. There have even been cases where the crooks have sent a key that has proved utterly ineffective in reversing the applied encryption.

All this shows there is no guarantee for the future of your files no matter how strictly you follow the ransom payment instructions. That’s why many victims seek alternatives that don’t involve giving money to some online crooks. The removal guide below is one such alternative that focuses on how to remove the Qoqa infection and how to potentially recover some of the files.


Data Recovery ToolNot Available
Detection Tool

*Qoqa is a variant of Stop/DJVU. Source of claim SH can remove it.

Remove Qoqa Virus

To remove the Qoqa virus, you have to find the program that infected you with it, delete it, then quit any malicious processes in the system, and restore the system settings that the malware has modified.

  1. See if there are questionable and potentially harmful programs in Programs and Features and eliminate them.
  2. Quit whatever malware processes you find in the Task Manager and then delete their files.
  3. Delete any rogue Startup items and Registry items that may have been created by the virus.
  4. To remove the Qoqa virus, go to each of the next folders and delete any harmful files stored in them. The folders are AppData, LocalAppData, ProgramData, WinDir, and Temp.

This was only a summary of the removal process that you must complete – for a more detailed and in-depth explanation, please, read on.

Expanded Removal Guide


Go to Control Panel > Programs > Programs and Features, search the list for programs you aren’t familiar with or ones that may be related to Qoqa and if you think that any of the programs listed there is malicious, be sure to delete it. To delete a program from that list, first click on it, then click on Uninstall, and complete whatever steps are shown in the uninstallation manager (those steps may vary). In some cases, the uninstaller could ask you if you’d prefer to keep custom settings for the program you are trying to delete or other similar data – do not agree to that, make sure that everything gets deleted.

Tip: Usually, if a malicious program is the reason behind the infection with Qoqa, it is likely that said program would have been added to the system not long before you realized that the computer has been compromised. Look at the installation dates of the different programs to help you determine which of the items there may potentially be related to Qoqa.




*Qoqa is a variant of Stop/DJVU. Source of claim SH can remove it.

Press the Winkey or click on the Start Menu icon, type in the Start Menu Task Manager, and press Enter to start the Task Manager app.

Check the Processes tab for anything unusual or suspicious such as a process or processes with odd-looking names that are using considerable amounts of CPU and RAM (sorting the items in the Processes tab by memory or CPU consumption will help you see which are the most resource0intensive ones).

If you notice anything that you deem potentially unsafe, search the internet for more information about that process and if there are articles or posts on security forums that state the process you looked up may be harmful, go to the file location of that process by right-clicking on its entry and selecting the first option.

Next, scan each file that you find in the file location folder with the help of the powerful online malware scanner we’ve shared below:

Each file will be scanned with up to 64 antivirus programs to ensure maximum accuracy
This scanner is free and will always remain free for our website's users.
This file is not matched with any known malware in the database. You can either do a full real-time scan of the file or skip it to upload a new file. Doing a full scan with 64 antivirus programs can take up to 3-4 minutes per file.
Drag and Drop File Here To Scan
Drag and Drop File Here To Scan
Analyzing 0 s
Each file will be scanned with up to 64 antivirus programs to ensure maximum accuracy
    This scanner is based on VirusTotal's API. By submitting data to it, you agree to their Terms of Service and Privacy Policy, and to the sharing of your sample submission with the security community. Please do not submit files with personal information if you do not want them to be shared.
    Task Manager1

    If you come across one or more files that the scanner detects as threats, return to the Task Manager (without closing the location folder), and quit the suspicious process (right-click > End Process).

    Following this, delete the files in the location folder and then the folder itself. If you cannot delete one or more of its files, leave them as they are for now and return to try to delete them again at the end of the guide.

    Task Manager2

    Tip: If there are articles/posts from security experts shared on trusted sites that say the process you suspect is indeed malicious, disable that process and get rid of its data even if not a single file got flagged as a threat.


    *Qoqa is a variant of Stop/DJVU. Source of claim SH can remove it.

    Use the guide on this link to put your computer into Safe Mode – this should help with the completion of the next steps and prevent the malware from starting its processes all over again.


    Open the Start Menu, paste this “notepad %windir%/system32/Drivers/etc/hosts” in its search field, press the Enter button, and, iftou have to select a program to acces the file, click on Notepad.

    Next, copy everything from the text in the Hosts text file that is written below “Localhost” and send it to our team down in the comments. Once someone has a look at the comment you’ve sent us, you will receive a reply with instructions on what to do next.

    If there’s nothing below “Localhost“, there’s no need to do anything in the Hosts file, so you should simply close it.


    Next, select the Start Menu Again, write msconfig, press Enter, and, in the Startup tab, search for questionable items that you do not recognize. Any item that looks like a threat or that you aren’t familiar with needs to be unchecked, after which you should select OK to apply the changes.


    Before you continue, be warned that while completing this step, you must be careful not to delete any items that are from your system and not from the virus as this could cause system problems. When in doubt, it’s best that you contact us through the comments and as us for assistance.

    Press Winkey and R from the keyboard, type in the window that pops-up regedit, hit the Enter button again, and then select the Yes button in case the Registry Editor requests a permission to make changes in the system.

    In the Editor, go to Edit > Find, type Qoqa in the search box, and launch the search. You should delete whatever gets found and search again to see if there are more items that need to be deleted. Make sure that there are no Qoqa items left in the Registry.

    1 1

    Next, manually search in the next three locations for items with suspicious names – long names with random numbers and letters in them. One example of such a suspiciously-named item would be “f984yh09rjb092tu-359yu6yh0ujr09u”.

    • HKEY_CURRENT_USER > Software
    • HKEY_CURRENT_USER > Software > Microsoft > Windows > CurrentVersion > Run
    • HKEY_CURRENT_USER > Software > Microsoft > Internet Explorer > Main

    Visit each of the folders that we’ve listed below by placing the folder’s name along with the “%” symbols (as shown below) in the Start Menu and hitting Enter.

    • %AppData%
    • %LocalAppData%
    • %ProgramData%
    • %WinDir%
    • %Temp%

    Delete only the most recent files (files created after the malware infected you) in all folders except Temp – in the Temp folder delete all files.

    Use Professional Removal Software It may not always be achievable to manually remove a Ransomware so, if the steps from above turned out to be ineffective for the deletion of Qoqa, we advise you to try to eliminate the virus with a professional virus-removal tool. It’s important to note that stealthy Trojan viruses are often used to both spread Ransomware and keep them active in the system for as long as possible. In other words, if you haven’t been able to remove Qoqa thus far, it’s highly possible that there’s also a hidden Trojan somewhere in the system, that is helping the Ransomware. Our suggestion in such situations is to use the advanced malware-deletion tool that you will find linked on this page – the powerful anti-malware program will not only clean your system from any rogue and harmful software but also keep it safe and protect it from potential future threats.

    How to Decrypt Qoqa files

    The decryption of Ransomware-encrypted files is a process different from the removal of the actual virus. If Qoqa has locked-up any sensitive and important files that you wish to restore, then you should have a look at our How to Decrypt Ransomware article where you will find instructions on how to attempt to bring your data back without paying the ransom that the hackers require. However, remember that you must first make sure that the virus truly gone from your PC before you try to recover any data. If you still have any doubts that malware files may be hiding on your computer, use the free online scanner that is available on our site in order to test any files you deem suspicious and see if there’s harmful code contained in them.


    About the author


    Lidia Howler

    Lidia is a web content creator with years of experience in the cyber-security sector. She helps readers with articles on malware removal and online security. Her strive for simplicity and well-researched information provides users with easy-to-follow It-related tips and step-by-step tutorials.

    Leave a Comment

    We are here to help! Use SpyHunter to remove malware in under 15 minutes.

    Not Your OS? Download for Windows® and Mac®.

    * See Free Trial offer details and alternative Free offer here.

    ** SpyHunter Pro receives additional removal definitions and manual fixes through its HelpDesk in cases where they are needed.

    Spyware Helpdesk 1